repositories / bugabinga.net
bugabinga.net
personal infrastructure for bugabinga!
owned by admin
services/luci/entrypoint.sh
Raw#!/usr/bin/env bash
set -euo pipefail
sshd_config=/run/luci-sshd.conf
ssh_command=/run/luci-ssh-command
write_sshd_config() {
local name value escaped
cat >"${sshd_config}" <<'SSHD_CONFIG'
Port 2223
HostKey /data/ci/ssh/ssh_host_ed25519_key
PasswordAuthentication no
KbdInteractiveAuthentication no
AuthenticationMethods publickey
PermitRootLogin prohibit-password
AuthorizedKeysFile /data/ci/authorized_keys
ForceCommand /run/luci-ssh-command
DisableForwarding yes
AllowTcpForwarding no
X11Forwarding no
PermitTTY no
SSHD_CONFIG
printf '%s\n' '#!/usr/bin/env bash' >"${ssh_command}"
for name in \
LUCI_DATA_DIR \
LUCI_REPO_ROOTS \
LUCI_HTTP_ADDR \
LUCI_BASE_URL \
LUCI_INBOX_DIR \
LUCI_PODMAN_SOCKET \
LUCI_SSH_ADDR \
LUCI_SSH_AUTHORIZED_KEYS \
LUCI_THEME_CSS \
LUCI_DEFAULT_TIMEOUT \
LUCI_DEFAULT_MEMORY \
LUCI_DEFAULT_CPUS \
LUCI_CACHE_MAX_VERSIONS \
LUCI_CACHE_MAX_BYTES \
LUCI_LOG_LEVEL \
LUCI_PUBLISH_REGISTRY_AUTH_FILE \
LUCI_PUBLISH_PKG_ROOT \
LUCI_PUBLISH_SITE_ROOT; do
value="${!name:-}"
[[ -n "${value}" ]] || continue
[[ "${value}" != *$'\n'* && "${value}" != *$'\r'* ]] || {
echo "invalid newline in ${name}" >&2
exit 1
}
escaped="${value//\\/\\\\}"
escaped="${escaped//\"/\\\"}"
printf 'SetEnv %s="%s"\n' "${name}" "${escaped}" >>"${sshd_config}"
printf 'export %s=%q\n' "${name}" "${value}" >>"${ssh_command}"
done
printf '%s\n' 'exec /usr/local/bin/luci ssh' >>"${ssh_command}"
chmod 0755 "${ssh_command}"
}
stop_children() {
kill "${sshd_pid:-}" "${luci_pid:-}" 2>/dev/null || true
wait "${sshd_pid:-}" "${luci_pid:-}" 2>/dev/null || true
}
trap 'stop_children; exit 0' INT TERM
install -d -m 0700 /data/ci/ssh /run/sshd
if [[ ! -f /data/ci/ssh/ssh_host_ed25519_key ]]; then
ssh-keygen -q -t ed25519 -N '' -f /data/ci/ssh/ssh_host_ed25519_key
fi
/usr/local/bin/luci env-check
write_sshd_config
/usr/sbin/sshd -t -f "${sshd_config}"
/usr/sbin/sshd -D -e -f "${sshd_config}" &
sshd_pid=$!
/usr/local/bin/luci serve &
luci_pid=$!
set +e
wait -n "${sshd_pid}" "${luci_pid}"
status=$?
set -e
stop_children
exit "${status}"